Re: iDefense Security Advisory 10.10.06: FreeBSD ptrace PT_LWPINFO Denial of Service Vulnerability

2006-10-10 Thread Colin Percival
Bill Moran wrote: > Colin Percival <[EMAIL PROTECTED]> wrote: >> This is a local denial of service bug, which was fixed 6 weeks ago in HEAD ^^^ > That was what I expected. Section III seems to hint that it could be > used by an unprivilidged user to crash or lo

Re: iDefense Security Advisory 10.10.06: FreeBSD ptrace PT_LWPINFO Denial of Service Vulnerability

2006-10-10 Thread Colin Percival
Bill Moran wrote: > This report seems pretty vague. I'm unsure as to whether the alleged > "bug" gives the user any more permissions than he'd already have? Anyone > know any details? This is a local denial of service bug, which was fixed 6 weeks ago in HEAD and RELENG_6. There is no opportunit

Proposal: MAC_BIBA and real-world usage

2006-10-10 Thread Borja Marcos
Hello, Are there many people actually using the MAC subsystem in the real world? I have been working to set up a shared hosting webserver and I've stumbled against some limitations with the BIBA policy. In short, it's an excellent model, and can be used succesfully if applications are aw

Re: cvs commit: ports/multimedia/win32-codecs Makefile distinfo pkg-plist

2006-10-10 Thread Dmitry Pryanishnikov
Hello! On Sat, 7 Oct 2006, Jose Alonso Cardenas Marquez wrote: Modified files: multimedia/win32-codecs Makefile distinfo pkg-plist Log: - Add the REALPLAYER and QUICKTIME(off) OPTIONS. If QUICKTIME OPTION is off, this port could install without problem of vulnerabilities. - Bump PORTR